Forum Discussion
Send Event to Events Hub
- May 22, 2019
For alerts outbound, today we support the syslog model only. We have a public preview coming soon that will move AATP to a new portal. When moving to that portal, the event hubs model will work.
Hi
No you can send events to event hub then to Azure ATP. AATP collects its data from the sensor. You have to install the sensor on your domain controllers in Active Directory.
- archedmeerkatMay 22, 2019Copper Contributor
I understand we need the sensors to get the data into AATP, I was referring to Suspicious Activity and Health alerts being sent to Events Hub, rather than using a sensor to syslog the events to our SIEM. Just seems like a little cleaner solution for our environment, if available.
- Nicholas DiCola (SECURITY JEDI)May 22, 2019Former Employee
For alerts outbound, today we support the syslog model only. We have a public preview coming soon that will move AATP to a new portal. When moving to that portal, the event hubs model will work.
- bryanbDec 10, 2019Brass Contributor
Nicholas DiCola (SECURITY JEDI) Hello, I'm also looking at configuration options to forward ATP alerts to EventHub. Is the "ATP to a new portal." online now? If there are any documentation links you can provide that would be great.
Thanks!